Tenda AX-1806 Stack Overflow Vulnerability in WiFi MAC Filter Configuration Function Allowing Denial-of-Service

Vulnerability

A stack overflow vulnerability has been identified in the Tenda AX-1806 router, specifically in version 1.0.0.1. The issue arises in the deviceList parameter of the formSetWifiMacFilterCfg function. This vulnerability allows attackers to craft requests that cause a denial-of-service (DoS) condition by exploiting the stack overflow to overwrite critical stack data, including the return address, leading to a crash of the device and persistent service disruption.

Impact

Exploitation of this vulnerability causes the router to crash, disrupting services and causing a persistent failure to function correctly.

Reproduction

The vulnerability can be reproduced by sending a POST request to the /goform/setWifiFilterCfg endpoint. The request must include a deviceList parameter with a crafted payload that exceeds 128 bytes, such as 156 bytes or longer, followed by a MAC address. This payload will overflow the stack buffer, allowing for control over the return address and potential execution of arbitrary code or causing a stable denial-of-service condition.

Added: Jan 21, 2026, 4:21 PM
Updated: Jan 21, 2026, 4:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.